节点文献

入侵检测系统的数据收集机制研究

Research on Data Collection Mechanisms for Intrusion Detection System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张然钱德沛包崇明栾钟治

【Author】 Zhang Ran 1,Qian Depei 1,Bao Chongming 2,Luan Zhongzhi 1 (1.School of Electronics and Information Engineering, Xi′an Jiaotong University, Xi′an 710049, China; 2.Institute of Software,Chinese Academy of Sciences)

【机构】 西安交通大学电子与信息工程学院中国科学院软件所西安交通大学电子与信息工程学院 710049西安710049西安

【摘要】 基于对入侵检测所采用的数据收集方法的分类和分析 ,提出了一种基于多代理的分布式数据收集模型 ,介绍了该模型的数据收集方法和协同检测过程 .该模型分别在网络的关键入口处以及主机的重要应用和网络接口处部署检测代理 ,各检测代理根据不同情况采用不同的数据收集方法对各种可疑数据进行收集 ,并通过协调代理对下层检测代理提交的数据进行协同分析 .结果表明 ,这种数据收集模型为协同检测奠定了基础 ,提高了对分布式攻击的检测能力

【Abstract】 Based on the classification and analysis of different data collection methods used in intrusion detection. a model of multi agent in view of data collection is put forward, and the corresponding data collection methods and process of collaborative detection are introduced. This model deploys individually detection agents on the primary entrance of network and network interfaces of the hosts with the important applications. Every agent uses several respective methods to collect suspicious data over against the different situations, and coordination agent analyses cooperatively the data submitted by lower detection agents. It is shown that this model of data collection establishes the basis of collaborative detection and greatly improves the capability of detecting distributed attacks.

【基金】 “九七三”国家重点基础研究项目 (G19990 32 710 ) ;国家自然科学基金资助项目 (90 10 40 2 2 ) .
  • 【文献出处】 西安交通大学学报 ,Journal of Xi’an Jiaotong University , 编辑部邮箱 ,2003年04期
  • 【分类号】TP393.08
  • 【被引频次】10
  • 【下载频次】102
节点文献中: 

本文链接的文献网络图示:

本文的引文网络